# Index Data Missing from "Discover"

**URL:** <https://discuss.elastic.co/t/index-data-missing-from-discover/59585>\
**Category:** Kibana\
**Created:** [September 1, 2016, 5:35pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585 "2016-09-01T17:35:28Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 1, 2016, 5:35pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/1 "2016-09-01T17:35:28Z")

</div>

- I am viewing the data of index-2016.09.01 from kibana, which i parsed yesterday evening. I can find this index in Setting. However, when i go to Discover, it is not available. Setting the time to "yesterday" or "the day before yesterday" don't work as well.  
Would you have any idea why? This situation happens before as well.

- also i encountered the problem of "**Field data loading is forbidden on [date]**" when i try to view dates fields (their data type is date). Any idea why this happens?

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [September 1, 2016, 7:33pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/2 "2016-09-01T19:33:24Z")

</div>

Hi Allie,

> I am viewing the data of index-2016.09.01 from kibana, which i parsed yesterday evening. I can find this index in Setting. However, when i go to Discover, it is not available.

What happens if you make the following API call against Elasticsearch directly?

`GET index-2016.09.01/_search`

Do you get any results back?

> also i encountered the problem of "Field data loading is forbidden on [date]"

What does the Elasticsearch mapping for this field look like? You can retrieve the mapping by calling the `GET <index name>` Elasticsearch API.

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 1, 2016, 7:53pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/3 "2016-09-01T19:53:20Z")

</div>

- 1, i write this **command** : curl -XGET '[http://localhost:9200/index-2016.09.01/\_search](http://localhost:9200/index-2016.09.01/_search)'. **This is the response** :  
{"error":{"root\_cause":[{"type":"index\_not\_found\_exception","reason":"no such index","resource.type":"index\_or\_alias","[resource.id](http://resource.id)":"index-2016.09.01","index":"index-2016.09.01"}],"type":"index\_not\_found\_exception","reason":"no such index","resource.type":"index\_or\_alias","[resource.id](http://resource.id)":"index-2016.09.01","index":"index-2016.09.01"},"status":404}  
**(but i can see this index in ES head and Kibana Setting. The command works for other previous index as well)**

- 2, **my command:** curl -XGET '[http://localhost:9200/date](http://localhost:9200/date)'  
**response is similar below:**  
{"error":{"root\_cause":[{"type":"index\_not\_found\_exception","reason":"no such index","resource.type":"index\_or\_alias","[resource.id](http://resource.id)":"date","index":"date"}],"type":"index\_not\_found\_exception","reason":"no such index","resource.type":"index\_or\_alias","[resource.id](http://resource.id)":"date","index":"date"},"status":404}

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [September 1, 2016, 8:03pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/4 "2016-09-01T20:03:37Z")

</div>

For 1:

It appears there is no index named `index-2016.09.01` in Elasticsearch. Can you go to the index patterns view in Kibana Settings and hit the refresh button for this index? What does that do?

Also, can you run `curl -X GET 'http://localhost:9200/_cat/indices`? That will tell us what indices you actually have in Elasticsearch.

For 2:

In your curl request, "date" needs to be replaced with the name of the _index_ in which "date" is a field. When you encountered the "Field data loading..." error, which index were you working with?

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 1, 2016, 8:18pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/5 "2016-09-01T20:18:03Z")

</div>

- 1, yes i do have 2016.09.01 index as below shows. However, Kibana **Discover** says "No Result Found". I now can find it in **yesterday** though. In Setting views, everything shows normal. **I am very afraid tomorrow or next week it disappeared again.**

yangyan-osx:2.3.5 yangyan$ curl -XGET '[http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices)'  
yellow open data 5 1 1 0 3.7kb 3.7kb  
yellow open logstash-2016.08.31 5 1 1 0 7.8kb 7.8kb  
yellow open logstash-2016.08.30 5 1 9584 0 1.2mb 1.2mb  
yellow open logstash-2016.09.01 5 1 3004283 0 276mb 276mb  
yellow open .marvel-es-1-2016.08.26 1 1 46371 464 14.6mb 14.6mb  
yellow open .marvel-es-data-1 1 1 14 6 28.1kb 28.1kb  
yellow open .kibana 1 1 29 2 80.2kb 80.2kb  
yellow open my\_index 5 1 0 0 795b 795b  
yellow open .marvel-es-1-2016.08.19 1 1 361 0 122kb 122kb  
yellow open .marvel-es-1-2016.08.30 1 1 58219 406 19.8mb 19.8mb  
yellow open .marvel-es-1-2016.08.31 1 1 42430 432 13.6mb 13.6mb  
yellow open logstash-2016.08.26 5 1 9587 0 3.5mb 3.5mb  
yellow open logstash-2016.08.25 5 1 3 0 24.1kb 24.1kb  
yellow open .marvel-es-1-2016.09.01 1 1 24945 504 19.9mb 19.9mb

- 2, sorry corrected the command and below shows the **mapping** (looks ok for me):

{"logstash-2016.09.01":{"aliases":{},"mappings":{"logs":{"\_all":{"enabled":true,"omit\_norms":true},"dynamic\_templates":[{"message\_field":{"mapping":{"fielddata":{"format":"disabled"},"index":"analyzed","omit\_norms":true,"type":"string"},"match":"message","match\_mapping\_type":"string"}},{"string\_fields":{"mapping":{"fielddata":{"format":"disabled"},"index":"analyzed","omit\_norms":true,"type":"string","fields":{"raw":{"ignore\_above":256,"index":"not\_analyzed","type":"string"}}},"match":"_","match\_mapping\_type":"string"}}],"properties":{"@timestamp":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"},"@version":{"type":"string","index":"not\_analyzed"},"app\_id":{"type":"string","norms":{"enabled":false},"fielddata":{"format":"disabled"},"fields":{"raw":{"type":"string","index":"not\_analyzed","ignore\_above":256}}},"date":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"},"geoip":{"dynamic":"true","properties":{"ip":{"type":"ip"},"latitude":{"type":"float"},"location":{"type":"geo\_point"},"longitude":{"type":"float"}}},"locale":{"type":"string","norms":{"enabled":false},"fielddata":{"format":"disabled"},"fields":{"raw":{"type":"string","index":"not\_analyzed","ignore\_above":256}}},"member\_id":{"type":"long"},"p\_contentId":{"type":"long"},"p\_source":{"type":"string","norms":{"enabled":false},"fielddata":{"format":"disabled"},"fields":{"raw":{"type":"string","index":"not\_analyzed","ignore\_above":256}}},"p\_typeId":{"type":"long"}}},"default":{"\_all":{"enabled":true,"omit\_norms":true},"dynamic\_templates":[{"message\_field":{"mapping":{"fielddata":{"format":"disabled"},"index":"analyzed","omit\_norms":true,"type":"string"},"match":"message","match\_mapping\_type":"string"}},{"string\_fields":{"mapping":{"fielddata":{"format":"disabled"},"index":"analyzed","omit\_norms":true,"type":"string","fields":{"raw":{"ignore\_above":256,"index":"not\_analyzed","type":"string"}}},"match":"_","match\_mapping\_type":"string"}}],"properties":{"@timestamp":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"},"@version":{"type":"string","index":"not\_analyzed"},"geoip":{"dynamic":"true","properties":{"ip":{"type":"ip"},"latitude":{"type":"float"},"location":{"type":"geo\_point"},"longitude":{"type":"float"}}}}}},"settings":{"index":{"creation\_date":"1472689510073","refresh\_interval":"5s","number\_of\_shards":"5","number\_of\_replicas":"1","uuid":"eI7vz0K4TPObVuEIQWVVig","version":{"created":"2030599"}}},"warmers":{}}}

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [September 1, 2016, 9:29pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/6 "2016-09-01T21:29:44Z")

</div>

Oh, you are referring to _logstash_-2016.09.01. In your original post you said _index_-2016.09.01 so that confused me.

Based on the output of `GET /_cat/indices` it appears that there is data in the `logstash-2016.09.01` index. Would you mind pasting a screenshot of your _Settings_ \> _Indices_ page from Kibana?

As for the "field data loading..." error, do you get the error if you use the `@timestamp` field instead of the `date` field?

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 1, 2016, 10:14pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/7 "2016-09-01T22:14:26Z")

</div>

- 1, sorry for the mis-referral. Below is the screen shot of the setting page. i think it looks ok. However, the **Discover** page shows it is not available, unless i hit **yesterday** button.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/d7ffd3e76479dddd3caa3150415d82b0358864ae.png)

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0161a2e39319005300b3a07fca12a4d830f9a5fb.png)

- 2, **we can ignore this for now.** I think it is some initial setting problem when i first initialize the index in kibana.

Thanks!

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [September 1, 2016, 11:01pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/8 "2016-09-01T23:01:43Z")

</div>

What time zone are you in? I ask because I believe the reason you need to go to _yesterday_ for seeing data in the `logstash-2016-09-01` index is that the timestamps are indexed in UTC time. So if you are west of UTC, some part of yesterday would've been 2016-09-01 in UTC time.

Looking at your index patterns page screenshot, I _think_ what you really want here is to not have individual time-based-indices as separate index patterns. Instead I think you just want one index pattern that's `logstash-*` which will cover all time-based indices, past, present, and future. Then you can simply use the time picker in Kibana to narrow down the the desired time window instead.

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 1, 2016, 11:10pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/9 "2016-09-01T23:10:26Z")

</div>

You are right, I am America/Los\_angelos timezone, so i would go to yesterday for 09.01.  
Sometimes the time picker doesn't work as well. like this morning, (i am in afternoon now 4:09pm,), the **yesterday** , **this week** , both don't work...So my saved search would show no data available.

- Any connection issue for kibana possibly?
- And it seems like the issue of 2016.09.01 missing problem still doesn't get answered....

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [September 1, 2016, 11:26pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/10 "2016-09-01T23:26:48Z")

</div>

While you are on the Discover page, can you open your browser's Developer Tools console, Network tab.? Then set the timepicker to yesterday or this week.

You should see a request being made to a `_field_stats` endpoint and another request right after that to a `_msearch` endpoint. Could you open up the details of both requests and paste their responses here?

That'll help me figure out which indices are being queried and what time ranges are being used in the query.

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 1, 2016, 11:39pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/11 "2016-09-01T23:39:44Z")

</div>

Hi i set the time to this week and below is the screen shot. I wonder if it is the problem in no cache?

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/040f709870ba3a44fdb0696bd620c569b110f6cf.png)

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [September 2, 2016, 9:11pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/12 "2016-09-02T21:11:58Z")

</div>

Can you click on each of the 4 requests, one by one? This should display the details for each request. Can you share those details here please? Specifically I am looking for the body of each request and the body of each corresponding response. Thanks!

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 2, 2016, 11:07pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/13 "2016-09-02T23:07:23Z")

</div>

Hi Sure, the details are lengthy. And now the index is not available again unless i hit **this week.**

**Request:**  
{"index":["logstash-2016.09.01"],"ignore\_unavailable":true}  
{"size":500,"sort":[{"@timestamp":{"order":"desc","unmapped\_type":"boolean"}}],"query":{"filtered":{"query":{"query\_string":{"analyze\_wildcard":true,"query":"_"}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"gte":1472342400000,"lte":1472947199999,"format":"epoch\_millis"}}}],"must\_not":[]}}}},"highlight":{"pre\_tags":["@kibana-highlighted-field@"],"post\_tags":["@/kibana-highlighted-field@"],"fields":{"_":{}},"require\_field\_match":false,"fragment\_size":2147483647},"aggs":{"2":{"date\_histogram":{"field":"@timestamp","interval":"3h","time\_zone":"UTC","min\_doc\_count":0,"extended\_bounds":{"min":1472342400000,"max":1472947199999}}}},"fields":["\*","\_source"],"script\_fields":{},"fielddata\_fields":["date","@timestamp"]}

**Response:**  
{  
"responses": [{  
"took": 131,  
"timed\_out": false,  
"\_shards": {  
"total": 5,  
"successful": 5,  
"failed": 0  
},  
"hits": {  
"total": 3004283,  
"max\_score": null,  
"hits": [{  
"\_index": "logstash-2016.09.01",  
"\_type": "logs",  
"\_id": "AVbjSh\_ybIXpl-fj9r\_d",  
"\_score": null,  
"\_source": {  
"@timestamp": "2016-09-01T01:08:21.036Z",  
"app\_id": "as",  
"date": "2016-08-30T21:59:41.000Z",  
"member\_id": - 1,  
"locale": "en\_US",  
"p\_source": "jem",  
"p\_typeId": 3,  
"p\_contentId": null  
},  
"fields": {  
"date": [1472594381000],  
"@timestamp": [1472692101036]  
},  
"sort": [1472692101036]  
}, {  
"\_index": "logstash-2016.09.01",  
"\_type": "logs",  
"\_id": "AVbjSh\_ybIXpl-fj9r\_c",  
"\_score": null,  
"\_source": {  
"@timestamp": "2016-09-01T01:08:21.035Z",  
"app\_id": "as",  
"date": "2016-08-30T21:59:36.000Z",  
"member\_id": 29822052,  
"locale": "en\_US",  
"p\_source": "web",  
"p\_typeId": 2,  
"p\_contentId": 106924172  
},  
"fields": {  
"date": [1472594376000],  
"@timestamp": [1472692101035]  
},  
"sort": [1472692101035]  
}, { **repetitive pattern data**  
}{  
"\_index": "logstash-2016.09.01",  
"\_type": "logs",  
"\_id": "AVbjSh6hbIXpl-fj9r3W",  
"\_score": null,  
"\_source": {  
"@timestamp": "2016-09-01T01:08:20.737Z",  
"app\_id": "as",  
"date": "2016-08-30T21:10:04.000Z",  
"member\_id": - 1,  
"locale": null,  
"p\_source": "renew",  
"p\_typeId": 3,  
"p\_contentId": null  
},  
"fields": {  
"date": [1472591404000],  
"@timestamp": [1472692100737]  
},  
"sort": [1472692100737]  
}  
]  
},  
"aggregations": {  
"2": {  
"buckets": [{  
"key\_as\_string": "2016-08-28T00:00:00.000Z",  
"key": 1472342400000,  
"doc\_count": 0  
}, {  
"key\_as\_string": "2016-08-28T03:00:00.000Z",  
"key": 1472353200000,  
"doc\_count": 0  
}, { **repetitive pattern again till end**  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:39pm UTC](https://discuss.elastic.co/t/index-data-missing-from-discover/59585/14 "2017-07-06T13:39:37Z")

</div>


